Mythic C2 Activity at Internet Scale
Mythic is an open-source collaborative command-and-control framework with plugin-based architecture supporting multiple agent types and transport profiles. It features a web-based operator interface used by red teams for authorized engagements, though threat actors have also deployed it in unauthorized intrusions. Analysis identifies 131 unique hosts exposing Mythic on the public Internet, with 115 carrying default certificate configurations. The infrastructure spans predominantly DigitalOcean, AWS, and Azure environments, concentrated in the United States, Hong Kong, and China. Default deployment artifacts including TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains enable detection. Multi-framework clusters suggest training environments, while isolated deployments with custom domains and staged payloads indicate operational use with Discord-based transports and steganographic techniques.
AI Analysis
Technical Summary
Mythic is a collaborative open-source C2 framework featuring a plugin-based architecture supporting multiple agent types and transport profiles. It provides a web-based operator interface primarily for authorized red team engagements but has also been deployed by unauthorized threat actors. An analysis identified 131 unique hosts exposing Mythic C2 infrastructure on the public Internet, with 115 using default certificate configurations. The infrastructure spans major cloud providers including DigitalOcean, AWS, and Azure, with geographic concentration in the United States, Hong Kong, and China. Default deployment artifacts such as TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains facilitate detection. The presence of multi-framework clusters suggests training environments, whereas isolated deployments with custom domains and staged payloads indicate operational use involving Discord-based transports and steganographic techniques.
Potential Impact
The exposure of Mythic C2 infrastructure on the public Internet, especially with default certificate configurations, increases the risk of unauthorized access and misuse by threat actors. Operational deployments using advanced transport methods like Discord and steganography may enable stealthy command-and-control communications, complicating detection and response efforts. The presence of these infrastructures across major cloud providers and multiple countries indicates a broad potential attack surface.
Mitigation Recommendations
No official patch or fix is applicable as this is an open-source framework used legitimately and illegitimately. Detection can be enhanced by monitoring for default Mythic TLS certificates (O=Mythic), port 7443 responses, and internal PKI chains. Network defenders should identify and investigate exposed Mythic C2 infrastructure, especially those using default configurations. Harden deployments by replacing default certificates and restricting public exposure. Monitor for indicators such as the listed IP addresses. Since this is not a software vulnerability but an adversary infrastructure, mitigation focuses on detection and blocking unauthorized use.
Indicators of Compromise
- ip: 142.93.52.11
- ip: 65.87.7.11
- ip: 194.26.192.117
- ip: 68.178.205.17
- ip: 192.169.176.54
- ip: 68.178.202.150
- ip: 170.64.183.242
Mythic C2 Activity at Internet Scale
Description
Mythic is an open-source collaborative command-and-control framework with plugin-based architecture supporting multiple agent types and transport profiles. It features a web-based operator interface used by red teams for authorized engagements, though threat actors have also deployed it in unauthorized intrusions. Analysis identifies 131 unique hosts exposing Mythic on the public Internet, with 115 carrying default certificate configurations. The infrastructure spans predominantly DigitalOcean, AWS, and Azure environments, concentrated in the United States, Hong Kong, and China. Default deployment artifacts including TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains enable detection. Multi-framework clusters suggest training environments, while isolated deployments with custom domains and staged payloads indicate operational use with Discord-based transports and steganographic techniques.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Mythic is a collaborative open-source C2 framework featuring a plugin-based architecture supporting multiple agent types and transport profiles. It provides a web-based operator interface primarily for authorized red team engagements but has also been deployed by unauthorized threat actors. An analysis identified 131 unique hosts exposing Mythic C2 infrastructure on the public Internet, with 115 using default certificate configurations. The infrastructure spans major cloud providers including DigitalOcean, AWS, and Azure, with geographic concentration in the United States, Hong Kong, and China. Default deployment artifacts such as TLS certificates with O=Mythic subjects, port 7443 responses, and internal PKI chains facilitate detection. The presence of multi-framework clusters suggests training environments, whereas isolated deployments with custom domains and staged payloads indicate operational use involving Discord-based transports and steganographic techniques.
Potential Impact
The exposure of Mythic C2 infrastructure on the public Internet, especially with default certificate configurations, increases the risk of unauthorized access and misuse by threat actors. Operational deployments using advanced transport methods like Discord and steganography may enable stealthy command-and-control communications, complicating detection and response efforts. The presence of these infrastructures across major cloud providers and multiple countries indicates a broad potential attack surface.
Defensive Guidance
No official patch or fix is applicable as this is an open-source framework used legitimately and illegitimately. Detection can be enhanced by monitoring for default Mythic TLS certificates (O=Mythic), port 7443 responses, and internal PKI chains. Network defenders should identify and investigate exposed Mythic C2 infrastructure, especially those using default configurations. Harden deployments by replacing default certificates and restricting public exposure. Monitor for indicators such as the listed IP addresses. Since this is not a software vulnerability but an adversary infrastructure, mitigation focuses on detection and blocking unauthorized use.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://censys.com/blog/mythic-c2"]
- Pulse Id
- 6aaa401dbc68ca971dbb0508
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip142.93.52.11 | CC=US ASN=AS14061 digitalocean llc | |
ip65.87.7.11 | CC=US ASN=AS25752 methean professional llc | |
ip194.26.192.117 | CC=DE ASN=AS210558 1337 services gmbh | |
ip68.178.205.17 | CC=US ASN=AS26496 godaddy.com llc | |
ip192.169.176.54 | CC=US ASN=AS398101 godaddy.com llc | |
ip68.178.202.150 | CC=US ASN=AS26496 godaddy.com llc | |
ip170.64.183.242 | CC=US ASN=ASNone |
Threat ID: 6aaa772855bf5e2cf571930e
Added to database: 09/16/2026, 11:02:00 UTC
Last enriched: 09/16/2026, 11:18:17 UTC
Last updated: 09/17/2026, 04:22:03 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.